CVE-2022-2926

MEDIUM

Adobe Download Manager < 3.2.55 - Authenticated Path Traversal via Unvalidated Setting

Title source: llm
STIX 2.1

Description

The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/2a440e1a-a7e4-4106-839a-d93895e16785

Scores

CVSS v3 4.9
EPSS 0.0132
EPSS Percentile 67.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
adobe/download_manager < 3.2.55
Published Sep 26, 2022
Tracked Since Feb 18, 2026